API Terms of Use
Effective 2026-06-21 · 2026-06-21
hey ema — API Terms of Use
Effective date: 2026-06-21 Last updated: 2026-06-21
1. Purpose and scope
These API Terms of Use (API Terms) govern programmatic and technical access to Hey ema — including HTTP APIs, webhooks, authentication flows, API keys, SDKs, client libraries, OpenAPI specifications, and any other machine-readable interfaces through which Hey ema is accessed (APIs).
These API Terms apply to:
- Customers and their Authorised Users;
- End Users who access APIs directly or through scripts or integrations; and
- any other person who accesses, probes, documents, or interacts with Hey ema APIs, whether or not they have a contract with Hey ema.
These API Terms are incorporated by reference into the Master Subscription Agreement (H1) for Customers, the SaaS End User Terms of Use (H10) for End Users, and the End User Licence Agreement (H9) for installable components that communicate with Hey ema APIs. They supplement the Acceptable Use Policy (H5). If there is a conflict about API or programmatic access, these API Terms prevail over the AUP and Terms to that extent.
2. No licence except as expressly granted
2.1 Observing traffic is not permission. Merely using Hey ema through a web browser, mobile application, or add-in, or observing network traffic, API responses, authentication headers, or documentation, does not grant you any licence to access Hey ema programmatically or to use Hey ema's APIs, schemas, or protocols for any other purpose.
2.2 Authorised access only. You may access Hey ema APIs only:
- (a) through the official Hey ema user interfaces for their intended purpose;
- (b) through documented public endpoints for the limited, unauthenticated uses they are designed for (for example embedded forms, calendar feeds, or public catalogue pages);
- (c) using API keys, service accounts, or OAuth credentials issued to you or your Customer for integration purposes, within the scope of that issuance; or
- (d) where Hey ema has given you prior written authorisation.
2.3 Documentation is confidential. Unless Hey ema publishes documentation for general public use, API specifications, OpenAPI documents, internal admin API references, and related materials are confidential to Hey ema and the Customer. You must not copy, distribute, or disclose them except as needed for authorised integration work within your organisation.
3. Prohibited conduct
Except where Applicable Law expressly permits the activity and these API Terms cannot lawfully prohibit it, you must not:
- (a) scrape, crawl, harvest, or bulk-extract data from Hey ema APIs or interfaces, or systematically download content for republication, resale, or building a competing product or dataset;
- (b) reverse engineer, decompile, disassemble, or derive non-public protocols, authentication or signing logic, token formats, rate-limit behaviour, tenant-isolation rules, or undocumented endpoints — except as permitted by §8;
- (c) circumvent or attempt to circumvent rate limits, access controls, authentication, billing meters, feature flags, tenant boundaries, or other technical restrictions;
- (d) operate an alternate client, wrapper, proxy, mirror, or "API-as-a-service" on top of Hey ema without Hey ema's written consent;
- (e) share, pool, resell, or sublicense API keys, session tokens, or credentials, or use one account or key to automate access on behalf of unrelated tenants or third parties;
- (f) probe, scan, or test the vulnerability of Hey ema except under the Responsible Disclosure Policy (H14);
- (g) use Hey ema APIs to develop or train a product or model that competes with Hey ema, or to extract data for model training, except as expressly permitted in the AI / Data Use Addendum (H4);
- (h) misrepresent your identity, authority, or the Customer on whose behalf you act;
- (i) interfere with or disrupt Hey ema, its networks, or other users' access, including by excessive automated requests, denial-of-service activity, or resource exhaustion; or
- (j) use any API response, schema, error format, or documentation to replicate Hey ema's service design for an unauthorised competing offering.
4. API keys, service accounts, and credentials
4.1 API keys and service accounts are personal to the issuing Customer, non-transferable, and revocable at any time.
4.2 The Customer is responsible for all activity conducted with its API keys and for ensuring Authorised Users with access to keys or API documentation comply with these API Terms.
4.3 You must store credentials securely, rotate them when compromise is suspected, and never embed them in public repositories, client-side code exposed to end users, or shared documents.
5. Intended use of public endpoints
Some Hey ema endpoints are intentionally available without authentication for specific embed, registration, kiosk, or public catalogue purposes. Use of those endpoints is permitted only within their documented purpose and at reasonable volume. High-volume harvesting, mirroring, or use that places an unreasonable load on Hey ema is prohibited even where no login is required.
6. Data export and retention
Export of Customer Data must use intended export features or documented APIs provided for that purpose. You must not use APIs to assemble a substitute export pipeline that exfiltrates data at a scale or frequency beyond normal product use, or in breach of the DPA, Privacy Policy, or Customer instructions.
7. Intellectual property
Hey ema owns all intellectual property in Hey ema's APIs, request and response formats, OpenAPI specifications, documentation, and the structure and selection of data fields exposed through APIs. No rights are granted except as expressly stated in the MSA, EULA, or these API Terms.
8. Interoperability and security research
8.1 Interoperability. If Applicable Law gives you a right to reproduce or adapt Hey ema software or interfaces for interoperability (including, in Australia, under s 47D of the Copyright Act 1968 (Cth)), you may exercise that right only after giving Hey ema written notice and a reasonable opportunity to provide the information necessary to achieve interoperability without reverse engineering.
8.2 Security research. Good-faith security research is welcome under the Responsible Disclosure Policy (H14). Research outside that policy, or that exceeds its scope, is unauthorised.
9. Monitoring and enforcement
9.1 Hey ema may monitor, log, throttle, block, or rate-limit API and documentation access for security, abuse prevention, billing, and compliance purposes. Access to confidential API documentation is logged.
9.2 Hey ema may suspend or revoke API keys, accounts, or documentation access immediately and without cure period where it reasonably believes these API Terms, the AUP, or Applicable Law have been breached, or where continued access poses a security or legal risk. For Customers, this is without limiting Hey ema's rights under the MSA.
9.3 Hey ema may preserve relevant logs and disclose information to competent authorities where required or permitted by law.
10. Relationship to customer-configured integrations
Where a Customer enables third-party integrations (for example Slack, Microsoft 365, or accounting systems), those integrations must comply with these API Terms and the AUP. Third-party providers chosen by the Customer are the Customer's responsibility, as described in the Sub-processor List (H7) §3.5.
11. Changes
Hey ema may update these API Terms in accordance with the change process in the MSA (for Customers) or by posting an updated version at https://heyema.app/docs/api-terms. Material changes that adversely affect Customers are notified as set out in the MSA. Continued API access after the effective date of an update constitutes acceptance to the extent permitted by Applicable Law.
12. Contact
Questions about these API Terms: legal@heyema.com. Report abuse: abuse@heyema.com. Security research: security@heyema.com (see Responsible Disclosure Policy).